News Room
16
Share
Lazarus Group Integrates CVE-2026-68820 Zero-Day into FudModule Rootkit Targeting Global Defense Sector
criticalZero-Day Exploits

Lazarus Group Integrates CVE-2026-68820 Zero-Day into FudModule Rootkit Targeting Global Defense Sector

North Korean APT Lazarus is actively exploiting a Windows kernel zero-day (CVE-2026-68820) to deploy an updated FudModule rootkit, bypassing EDR and Smart App Control in defense-sector attacks.

19 August 2026Last updated 20 August 20264 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-68820
Source:
Check Point Research
Read Time:
4 min

Executive Summary

Recent intelligence confirms that the North Korean state-sponsored actor Lazarus Group (also known as Diamond Sleet) has successfully integrated a newly disclosed Windows kernel zero-day, tracked as CVE-2026-68820, into their sophisticated FudModule rootkit. This vulnerability, a use-after-free flaw in the Ancillary Function Driver for WinSock (afd.sys), was patched in the August 2026 Patch Tuesday cycle but saw extensive active exploitation prior to the release of security updates. The campaign, identified as a new iteration of 'Operation Dream Job,' specifically targets high-value individuals within the defense, aerospace, and aviation sectors across Europe and India. By leveraging this zero-day, Lazarus achieves SYSTEM-level privileges, allowing them to bypass modern security mitigations including Endpoint Detection and Response (EDR) systems and Windows Smart App Control.

Threat Analysis

The exploitation of CVE-2026-68820 represents a significant escalation in Lazarus Group's technical capabilities. Operation Dream Job typically begins with social engineering, where attackers pose as recruiters on professional networking platforms to deliver malicious payloads disguised as job descriptions or application tools. The shift toward kernel-mode exploitation via afd.sys indicates a strategic move to ensure persistence and stealth. By operating within the kernel, the FudModule rootkit can manipulate system memory directly, effectively blinding security software that resides in user-mode. This latest wave has shown a particular focus on organizations involved in sensitive military technology and satellite communications, suggesting a primary objective of strategic espionage and intellectual property theft.

Technical Details

CVE-2026-68820 is a high-severity use-after-free vulnerability located in the afd.sys driver, which serves as the entry point for the Windows Sockets API. The flaw is triggered when the driver fails to properly manage memory objects during specific socket operations, leading to a race condition. An attacker with local authenticated access can execute a specially crafted application to trigger this condition, resulting in an arbitrary memory write. Lazarus has weaponized this to gain SYSTEM privileges on Windows 11 builds 26100 and 26200. Once elevated, the updated FudModule rootkit employs Direct Kernel Object Manipulation (DKOM) to disable EDR telemetry. Notably, this version introduces a new technique to tamper with Smart App Control, a Windows security feature designed to block untrusted or potentially malicious applications, thereby facilitating the execution of subsequent stages of the attack chain without detection.

Attribution Assessment

Encrygma analysts, in alignment with reports from Check Point Research and Microsoft MSTIC, attribute this activity to the Lazarus Group with high confidence. The attribution is based on the use of the FudModule rootkit, which is a signature tool of this actor, and the continuation of the 'Operation Dream Job' infrastructure. The targeting patterns, specifically focusing on defense contractors in regions of strategic interest to North Korea, further support this assessment. The sophistication of the afd.sys exploit suggests access to high-level exploit development resources, consistent with state-sponsored capabilities.

Implications

The successful deployment of a kernel-level rootkit via a zero-day vulnerability poses a critical risk to enterprise environments. Traditional security perimeters are insufficient against an adversary that can operate beneath the visibility of EDR tools. For the defense sector, the potential for long-term, undetected data exfiltration of classified projects is high. Furthermore, the ability to bypass Smart App Control suggests that even hardened Windows 11 environments are vulnerable to this specific threat actor's current toolkit.

Recommendations

Organizations must prioritize the deployment of the August 2026 Microsoft security updates to mitigate CVE-2026-68820. Beyond patching, it is recommended to: 1. Implement strict application whitelisting and monitor for unauthorized kernel driver loading. 2. Enhance monitoring for anomalous socket activity and race condition patterns in kernel logs. 3. Conduct targeted threat hunting for indicators of the FudModule rootkit, specifically looking for DKOM-related memory artifacts. 4. Educate high-value targets on the risks of unsolicited recruitment offers and the dangers of downloading attachments from unverified sources.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo